cd /news/ai-safety/why-ai-sandbox-escapes-are-cybersecu… · home topics ai-safety article
[ARTICLE · art-88288] src=siliconangle.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Why AI sandbox escapes are cybersecurity’s newest attack surface

Rubrik Inc.'s Zero Labs threat research team discovered an AI sandbox escape in Microsoft Copilot that could allow attackers to gain command and control of hundreds or thousands of users' files, SharePoint files, and OneDrive data; Microsoft patched the flaw by mid-March after responsible disclosure. Joe Hladik, head of Zero Labs, said the underlying technique could apply to other AI copilots, and Rubrik's research found only 23% of security leaders have full visibility into AI agents in their environment.

read3 min views1 publishedAug 6, 2026
Why AI sandbox escapes are cybersecurity’s newest attack surface
Image: Siliconangle (auto-discovered)

Why AI sandbox escapes are cybersecurity’s newest attack surface

Security researchers have spent the past year watching AI accelerate attacks that already exist. A harder question is whether AI can create attack techniques that didn’t exist before. An AI sandbox escape — where an attacker breaks out of the isolated environment meant to contain an AI assistant — is one of the clearest signs yet that it can.

Joe Hladik (pictured), head of Zero Labs, the threat research arm of Rubrik Inc., the data security firm, built his team’s research practice around backup data — a source few others study. This year that focus turned to how employees use AI day to day, starting with the Copilot assistant used by roughly 20 million people and about 90% of the Fortune 500.

“No one’s looking at backup data,” Hladik said. “We found it to be a viable place to find actual intelligence to act upon.”

Hladik spoke with Krista Case at Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed the AI sandbox escape Rubrik Zero Labs found in Microsoft Copilot and what it means for defending AI agents. ( Disclosure below.)*

Inside the AI sandbox escape that hit Microsoft Copilot

The discovery happened in February, Hladik said, and Rubrik Zero Labs followed responsible disclosure, engaging Microsoft before going public; Microsoft patched the flaw by mid-March. The specific vulnerability is fixed, though the underlying technique — breaking out of Copilot’s sandbox to reach Azure’s backend — could apply to other AI copilots, Hladik said. Researcher Ori Lahav presents the full findings at Black Hat this week.

“[That] would allow you to get command and control of probably hundreds, thousands, or much more, depending on the volume of what exists within that tenant of users’ files, SharePoint files, OneDrive, whatever,” Hladik said. “It’s a major, major find.”

That visibility gap extends beyond this one flaw. Rubrik Zero Labs’ own research found only 23% of security leaders have full visibility into the AI agents already running in their environment, a gap Rubrik is racing to close with new AI agent governance tools unveiled this week.

“Agents are just bots with models,” Hladik said. “They’re a bot that asks a model, and then the model will tell them what to do, and then they act. It’s new, it’s cool, but at the same time, I’ve seen this before.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA: ( Disclosure: Rubrik sponsored this segment of theCUBE. Neither Rubrik nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)*

Photo: SiliconANGLE

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About SiliconANGLE Media

SiliconANGLE,

theCUBE Network,

theCUBE Research,

CUBE365,

theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

── more in #ai-safety 4 stories · sorted by recency
── more on @rubrik inc. 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/why-ai-sandbox-escap…] indexed:0 read:3min 2026-08-06 ·